
Senior Principal Reverse Engineering/Vulnerability Research Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Conduct vulnerability research and reverse engineering for client projects.
• Execute static and dynamic analysis utilizing disassemblers, debuggers, and fuzzing tools.
• Develop exploits by leveraging identified vulnerabilities.
• Share security research results internally and, when appropriate, with external parties.
• Guide and mentor fellow security researchers.
• Analyze and comprehend the functioning of various types of systems.
• Lead vulnerability research initiatives through multiple phases and iterations.
• Must be eligible to obtain and maintain a TS/SCI security clearance; only U.S. Citizens qualify for security clearances.
• Bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a related technical field, along with 11 years of professional experience.
• Experience in participating in Capture The Flag (CTF) events, hackathons, or other cybersecurity competitions.
• Familiarity with Ghidra, Binary Ninja, IDA, or other reverse engineering/disassembler tools.
• Proficient in Linux fundamentals, including sockets, file descriptors, networking, iptables, file systems, and kernel concepts.
• Capability to read and write in C and assembly languages as required, including ARM, MIPS, and x86_64 architectures.
• Understanding of programming fundamentals, particularly in networking, data structures, and data models.
• Knowledge of exploitation techniques, such as arbitrary read-write primitives, shellcoding, and return-oriented or jump-oriented programming.
• Proven experience in exploit creation targeting Android operating systems and Chrome web browsers.
• Preferred: currently holds a Top Secret security clearance.
• Preferred: experience in OS and kernel reverse engineering.
• Preferred: understanding of AFL++ or libFuzzer.
• Preferred: familiarity with SELinux, Seccomp, ASLR, and Control Flow Integrity (CFI).
• Preferred: strong knowledge of dynamic analysis using gdb/gdbserver and similar tools.
• Preferred: basic understanding of processor toolchains and Android NDK.
• Preferred: knowledge of Qemu or Unicorn emulation.
• Preferred: experience in identifying 0-day vulnerabilities and other security flaws.
• People-centric work environment.
• An atmosphere where innovation flourishes, careers develop, and individuals are appreciated.
• Equal opportunity employer.
Clarity Innovations, Inc.
Clarity Innovations, Inc.
Synthesia
Get handpicked remote jobs straight to your inbox weekly.